Knowledge Management

error in search splunk indexer

kjain041523
New Member

kjain041523_0-1775550170150.png

 

Labels (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

1. I'm not sure you meant an indexer in the topic. You typically don't search directly on the indexer if you have tiered architecture.

2. It's usually either because someone fiddled with the config and broke a TA itself or changed permissions so that the lookups are either undefined or (more frequent case) not available due to lack of permission for user's role.

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @kjain041523 

This error looks to relate to the Splunk_TA_paloalto app - have you customised this app in any way?

Specifically those two lookup definitions are referencing the lookup 'minemeldfeeds_lookup' which is a KVStore - do you have any issues with KV Store on your deployment? 

By default these lookup definitions and KV Store definitions are shared globally - have you changed the KV Store definition or permissions at all?

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

kknairr
Contributor

@kjain041523  The lookup error indicates Splunk is attempting to run automatic lookups that reference missing or misconfigured lookup files.

You can try to check the lookup definitions in Splunk Web under Settings > Lookups, confirm that the corresponding CSV files (minemeIdfeeds_src_lookup, minemeIdfeeds_dest_lookup) exist in the app’s lookups or directory. To fix the error, you may either restore the missing files or disable the lookup definitions if they are not needed. 

>>

If this post addressed your question, you can:

  • Give it karma to show appreciation 👍
  • Mark it as the solution if it solved your issue ✔️
  • Add a comment if you’d like more details ✏️

Acknowledging helpful answers keeps the community strong and motivates contributors to continue sharing their expertise.

>>

gcusello
SplunkTrust
SplunkTrust

Hi @kjain041523 ,

there's a lookup not found or not existent, probably an automatic lookup.

You shouls search it in the add-ons and check if it's present but not correctly shared or if it isn't present.

In the first case, you have to share it at Global level, in the second case, you have to create it.

Ciao.

Giuseppe

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...